Real-Time Cybersecurity Situation Awareness Through a User-Centered Network Security Visualization

dc.contributor.advisorElmqvist, Niklasen_US
dc.contributor.authorDeValk, Kaitlynen_US
dc.contributor.departmentComputer Scienceen_US
dc.contributor.publisherDigital Repository at the University of Marylanden_US
dc.contributor.publisherUniversity of Maryland (College Park, Md.)en_US
dc.date.accessioned2023-02-02T06:35:58Z
dc.date.available2023-02-02T06:35:58Z
dc.date.issued2022en_US
dc.description.abstractOne of the most common problems amongst cybersecurity defenders is lack of network visibility, leading to decreased situation awareness and overlooked indicators of compromise. This presents an opportunity for the use of information visualization in the field of cybersecurity. Prior research has looked at applying visual analytics to computer network defense, which has led to the development of visualizations for a variety of use cases in the security field. However, many of these visualizations do not consider user needs and requirements or require some predetermined user knowledge about the network to create the visuals, leading to low adoption in practice. With this in mind, I took a bottom-up, user-centered approach using interviews to gather user-desired components for the design, development, and evaluation of a network security visualization tool, called Riverside. I designed a visualization that attempts to balance providing a comprehensive view of an environment while supplying details-on-demand. Riverside’s key contribution is a data-driven, dynamic view of a network’s security state over time, meant to supplement an analyst’s real-time situation awareness of their network. Riverside’s system automatically partitions internal from external network components to visualize potential attack vectors across the entire environment. This research supports the need for further incorporation of users into the cybersecurity visualization development lifecycle. I call attention to key requirements for creating effective cybersecurity visualizations and specific use cases where visualizations can be leveraged to augment operational cybersecurity capabilities.en_US
dc.identifierhttps://doi.org/10.13016/ccqt-obfe
dc.identifier.urihttp://hdl.handle.net/1903/29696
dc.language.isoenen_US
dc.subject.pqcontrolledComputer scienceen_US
dc.subject.pquncontrolledCybersecurity situation awarenessen_US
dc.subject.pquncontrolledInformation visualizationen_US
dc.subject.pquncontrolledNetwork securityen_US
dc.titleReal-Time Cybersecurity Situation Awareness Through a User-Centered Network Security Visualizationen_US
dc.typeThesisen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
DeValk_umd_0117N_23043.pdf
Size:
3.38 MB
Format:
Adobe Portable Document Format